{
  "type": "malware",
  "spec_version": "2.1",
  "id": "malware--c009560a-f097-45a3-8f9f-78ec1440a783",
  "created": "2021-11-29T18:37:40.308Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "revoked": false,
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/software/S0663",
      "external_id": "S0663"
    },
    {
      "source_name": "HyperSSL",
      "description": "(Citation: Trend Micro Iron Tiger April 2021)"
    },
    {
      "source_name": "Soldier",
      "description": "(Citation: Trend Micro Iron Tiger April 2021)"
    },
    {
      "source_name": "FOCUSFJORD",
      "description": "(Citation: Trend Micro Iron Tiger April 2021)"
    },
    {
      "source_name": "Trend Micro Iron Tiger April 2021",
      "description": "Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.",
      "url": "https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "modified": "2025-10-21T23:26:56.446Z",
  "name": "SysUpdate",
  "description": "[SysUpdate](https://attack.mitre.org/software/S0663) is a backdoor written in C++ that has been used by [Threat Group-3390](https://attack.mitre.org/groups/G0027) since at least 2020.(Citation: Trend Micro Iron Tiger April 2021)",
  "is_family": true,
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_platforms": [
    "Windows",
    "Linux"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_domains": [
    "enterprise-attack"
  ],
  "x_mitre_version": "1.3",
  "x_mitre_attack_spec_version": "3.3.0",
  "x_mitre_aliases": [
    "SysUpdate",
    "HyperSSL",
    "Soldier",
    "FOCUSFJORD"
  ]
}